Okta: Breach Affected All Customer Support Users
ID: f2e35e9c-cd66-5f0b-9719-c978728e4f35
STIX ID: report--f2e35e9c-cd66-5f0b-9719-c978728e4f35
Feed Name: Krebs on Security
Okta disclosed that intruders accessed its customer support case management system in late September–October 2023, stealing authentication tokens for some customers (initially reported as files for 134 customers) and the names and email addresses of nearly all customer support system users; roughly 97% of exposed accounts contained only name and email, while about 3% included additional fields such as last login, username, phone number, SAML federation ID, company name, and job role. The company attributed the intrusion to a compromised service account credential that had been saved to an employee's personal Google account, highlighting elevated risk to Okta administrators and the potential for targeted phishing or account takeover if MFA is not enforced.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
